Cyphertree Cyphertree

Security & compliance

Your team's data, protected across Europe and India.

Every record moves to India under the EU's Standard Contractual Clauses, isolated so only you can reach it, and backed by contracts you can verify yourself. Built to satisfy both the EU GDPR and India's DPDP Act.

Lawful transfer

Moving data to India, on a lawful footing.

The first question a European legal team asks is simple: is it lawful to send employee data to India? The answer sits inside your contract, not in a promise.

Personal data transfers under the EU Standard Contractual Clauses (2021/914, Module Two), and India's Digital Personal Data Protection Act, 2023 is met on the Indian side. One dataset, both laws satisfied.

Access and isolation

Only your company can reach your data.

Each company's records are walled off from every other at the database itself. A single sign-in reaches one company's data and no one else's, enforced below the application where a leaked password still cannot cross the line.

Access is granted by role, reviewed on a schedule, and encrypted both in transit and at rest.

Encryption and audit

Contained, and always accounted for.

Data is encrypted end to end, and every change is written to an audit record: who changed what, and when. That record is tamper-evident, so it holds up as evidence.

If a question ever arises, there is a complete trail to answer it, ready to hand to a regulator.

Proof, not promises

Every contract, verifiable by anyone.

Each contract is signed to the EU's Advanced Electronic Signature standard and stamped with an independent RFC-3161 timestamp.

The signed document proves its own integrity, on its own, without relying on Cyphertree staying online. Proof you hold, rather than a promise you are given.

What's under the hood

The controls behind the promise.

EU Standard Contractual Clauses

Every EU-to-India transfer runs on the SCCs (2021/914, Module Two), pre-filled in your Data Processing Agreement.

Database-level isolation

Row-level security keeps one company's data unreachable from another's, enforced by the database, not just the app.

Encrypted in transit and at rest

TLS 1.3 on every connection and AES-256 for data at rest, across the whole platform.

Tamper-evident audit trail

Every change is logged to a forensic record — actor, before, after, timestamp — that cannot be edited away.

Verifiable e-signatures

Contracts signed to eIDAS Advanced Electronic Signature, timestamped to RFC-3161, verifiable by anyone holding the file.

GDPR and DPDP, together

Built to meet the EU GDPR and India's DPDP Act 2023 on the same records, for the Europe-India corridor.

BUILT QUIETLY IN PUNE · SHIPPING ACROSS EUROPE

See it work with your team.

20-minute demo with the founder. No slides, no pitch deck. We’ll set up a real employee live and you’ll watch payroll run on your numbers.